Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Fortinet NSE7_NST-7.2 Practice Exam with Questions & Answers

Questions 1

Which three conditions are required for two FortiGate devices to form an OSPF adjacency? (Choose three.)

Options:
A.

OSPF link costs match.

B.

OSPF interface priority settings are unique

C.

OSPF interface network types match

D.

Authentication settings match.

E.

OSPF router IDs are unique.

Fortinet NSE7_NST-7.2 Premium Access
Questions 2

Refer to the exhibit. whichcontains the output of diagnose vpn tunnellist.

NSE7_NST-7.2 Question 2

Which command will capture ESP traffic for the VPN named DialUp_0?

Options:
A.

diagnose sniffer packet any ‘host10.0.10.10’

B.

diagnose sniffer packet any ‘ip proto 50’

C.

diagnose sniffer packet any ‘esp and host 10*200.3.2’

D.

diagnose sniffer packet any ‘port 4500’

Questions 3

NSE7_NST-7.2 Question 3

Refer to the exhibit, which shows the output of a diagnose command.

What can you conclude from the RTT value?

Options:
A.

Its value represents the time it takes to receive a response after a rating request is sent to a particular server.

B.

Its value is incremented with each packet lost.

C.

It determines which FortiGuard server is used for license validation.

D.

lts initial value is statically set to 10.

Questions 4

Referto the exhibit, which shows oneway communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric.

NSE7_NST-7.2 Question 4

What three actions must you take to ensure successful communication? (Choose three.)

Options:
A.

Ensure the port for Neighbor Discovery has been changed.

B.

FortiGate must not be in NAT mode.

C.

Ensure TCP port 8013 is not blocked along the way

D.

You must authorize the downstream FortiGate on the root FortiGate.

E.

You must enable Security Fabric/Fortitelemetry on the receiving interface of the upstream FortiGate.

Questions 5

NSE7_NST-7.2 Question 5

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command

What two conclusions can you draw from the output? (Choose two.)

Options:
A.

FSSO is using agentless polling mode to detect logon events.

B.

The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on

C.

The logon event can be seen on the collector agent installed on Windows.

D.

FSSO is using DC agent mode to detect logon events.

Questions 6

Refer to the exhibit, which shows the output of diagnose syssessionstat. Which statement about the output shown in the exhibit is correct?

Options:
A.

AII the sessions in the session table are TCP sessions.

B.

162 sessions have been deleted because of memory page exhaustion.

C.

There are 166 TCP sessions waiting to complete the three-way handshake.

D.

There are two sessions that have not been removed in case of any out-of-order packets that arrive.

Questions 7

Refer to the exhibits.

NSE7_NST-7.2 Question 7

An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix.

Which two actions can the administrator take to fix this problem'' (Choose two.)

Options:
A.

Restart BGP using a soft reset, which forces both peers to exchange their complete BGP routing tables.

B.

Manually add the BGP route on FGT-A.

C.

Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0724.

D.

Use the set network-import-check disable command.

Questions 8

Which of the following regarding protocol states is true?

Options:
A.

proto_state=00 indicates that UDP traffic flows in both directions.

B.

proto_state-01 indicates an established TCP session.

C.

proto_state=10 indicates an established TCP session.

D.

proto state=01 indicates one-way ICMP traffic.

Questions 9

Which exchange lakes care of DoS protection in IKEv2?

Options:
A.

IKE_Req_INIT

B.

IKE_SA_INIT

C.

IKE_Auth

D.

Create_CHILD_SA

Questions 10

Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.

NSE7_NST-7.2 Question 10

What three conclusions can you draw from these log entries? (Choose three.)

Options:
A.

Remote registry is not running on the workstation.

B.

The FortiGate firmware version is not compatible with that of the collector agent

C.

DNS resolution is unable to resolve the workstation name.

D.

The user's status shows as "not verified" in the collector agent

E.

A firewall is blocking traffic to port 139 and 445.

Exam Code: NSE7_NST-7.2
Certification Provider: Fortinet
Exam Name: Fortinet NSE 7 - Network Security 7.2 Support Engineer
Last Update: Jul 13, 2025
Questions: 40
PDF + Testing Engine
$164.99
$57.75
Testing Engine
$124.99
$43.75
PDF (Q&A)
$104.99
$36.75

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.